Malware Families page 42 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Retro trojanspyware
Retro is a stealthy malware designed to evade detection while gathering sensitive information primarily from governmental and financial…
RevC2 ratbackdoor
RevC2 is a remote access trojan (RAT) primarily used for cyber espionage against government, financial, and technology sectors.
RevCode trojanspyware
RevCode is a sophisticated trojan frequently associated with targeted attacks against tech companies.
Revenant rat
According to its author, Revenant is a 3rd party agent for Havoc written in C, and based on Talon.
Revenge RAT rat
Also known as Revetrat. Revenge RAT is a freely available remote access tool written in .NET (C#).
Revenge Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Revenge-RAT rat
Revenge v0.1 was a simple tool, according to a researcher known as Rui, who says the malware’s author didn’t bother obfuscating the RAT’s…
ReverseRAT rat
ReverseRAT is a remote access trojan primarily used for espionage operations.
Reveton ransomware
Reveton is a type of ransomware known for displaying a lock screen imitating law enforcement agencies to trick users into paying a fine…
Reveton ransomware ransomware
A ransomware family that targets users from certain countries or regions.
Revive trojancredential-stealer
According to PCrisk, Revive is the name of a banking Trojan targeting Android users (customers of a specific Spanish bank).
Revolution ransomware
Revolution is a type of ransomware known for encrypting victims' data and demanding a ransom for its release.
Rex ratspyware
Rex is a sophisticated remote access tool used by threat actors for espionage operations, primarily targeting government and technology…
Reyptson ransomware
Reyptson is a ransomware that specifically targets users in Spain.
Rhadamanthys credential-stealer
According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected…
Rhino ransomware
Rhino is a ransomware variant known for encrypting files and demanding a ransom from victims.
Rhysida (ELF) ransomware
Rhysida is a ransomware family known for targeting sectors such as government and healthcare.
Rhysida (Windows) ransomware
Rhysida is a ransomware family that primarily targets organizations across various sectors, including healthcare, education, and government.
Rietspoof downloaderdropperbotnet
Rietspoof is malware that mainly acts as a dropper and downloader, however, it also sports bot capabilities and appears to be in active…
Rifdoor rat
Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.
Rijndael ransomware
Rijndael is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
Rikamanu backdoorrat
Rikamanu is an advanced persistent threat known for its backdoor and remote access trojan capabilities, primarily targeting governmental…
Riltok trojancredential-stealer
Riltok is banking malware that uses phishing popups to collect user credentials.
Rincrypt ransomware
Rincrypt is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
Rincux trojan
Rincux is a Trojan malware known for targeting financial institutions and technology sectors.
Ripper ATM trojan
Ripper ATM is a malware family designed to target and exploit ATM systems.
RiseLoader loaderdropper
RiseLoader is a new malware loader family first observed in October 2024.
RisePro credential-stealerdownloadertrojan
RisePro is a stealer that is spread through downloaders like win.privateloader.
Rising Sun backdoortrojan
Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019.
Roaming Mantis trojan
Roaming Mantis is an Android Trojan that has been predominantly spreading through DNS hijacking and smishing campaigns, targeting users…
RoarBAT wiper
According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.
RobbinHood ransomware
RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.
RobinHood ransomware
Also known as HelpYemen, RobbinHood. Detected in April 2019. Known for paralyzing the cities of Baltimore and Greenville. Probably also exfiltrate data
Roboto botnetddos
P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows…
Rockloader loader
Rockloader is a malware loader known for downloading additional malicious payloads onto infected systems.
Rofin
Rofin is a malware entity with limited available information, lacking a detailed description of its functionalities and target scope.
Roga ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Rogue
Rogue is a malware with limited publicly available information.
Rogue HT ransomware
Rogue HT is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
RogueRobin backdoorrat
RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.
RogueRobinNET backdoortrojan
RogueRobinNET is a .NET variant of the PS1.RogueRobin, known for targeting government and defense sectors in the Middle East.
Rokku ransomware
Rokku is a type of ransomware potentially associated with the Chimera malware family.
RollSling rat
RollSling is a Remote Access Trojan (RAT) used primarily for cyber-espionage purposes, targeting government and public sector organizations.
Rombertik spywarecredential-stealer
Also known as CarbonGrabber. Rombertik is a sophisticated spyware and credential-stealer known for its anti-analysis and destructive capabilities.
Romeo(Alfa,Bravo, ...) rat
Romeo is a remote access tool (RAT) used mainly for cyber espionage.
Rontok ransomware
Rontok is a ransomware type of malware designed to encrypt files on the infected system, demanding a ransom payment for their release.
Rook ransomware
Rook is a ransomware family known for targeting various sectors such as healthcare, financial services, and government entities.
Roopirs backdoortrojan
Roopirs is a sophisticated malware family known to target financial and government sectors, particularly in Eastern Europe.
Roopy
Roopy is a malware sample with limited information available.
Rootnik rootkittrojan
Rootnik is an Android-based malware family known for its ability to escalate privileges and maintain persistence.
Rorschach Ransomware ransomware
Also known as BabLock. Rorschach Ransomware, also known as BabLock, is a sophisticated ransomware strain designed to encrypt the victim's files and demand a…
Roseam loader
Also known as PisLoader. Roseam, also known as PisLoader, is a malware family primarily used as a loader for delivering various types of payloads.
RoshaLock ransomware
Ransomware Stores your files in a password protected RAR file
Roshtyak backdoor
A DLL backdoor distributed by Raspberry Robin.
RotaJakiro backdoor
RotaJakiro is a 64-bit Linux backdoor used by APT32.
Rotexy ransomwarespywaretrojan
Rotexy is an Android banking malware that has evolved over several years.
RotorCrypt(RotoCrypt, Tar) Ransomware ransomware
Also known as RotorCrypt, RotoCrypt, Tar Ransomware. This is most likely to affect English speaking users, since the note is written in English.
Rottie3 ratbackdoor
Rottie3 is a remote access trojan (RAT) that provides attackers with persistent backdoor access to compromised systems.
Rover spyware
Rover is malware suspected of being used for espionage purposes.
Rovnix loaderrootkit
Also known as BkLoader, Cidox, Mayachok. Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves.
Royal ransomware
Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023.
Royal DNS backdoor
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
Royal Ransom (ELF) ransomware
Also known as Royal, Royal_unix. According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be…
Royal Ransom (Powershell) downloaderransomware
Toolkit downloader used by Royal Ransomware group, involving GnuPG for decryption.
Royal Ransom (Windows) ransomware
Royal Ransom is a type of ransomware that targets various industries by encrypting data and demanding ransom payments for decryption keys.
RoyalCli backdoor
RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines.
RozaLocker Ransomware ransomware
Also known as Roza. This is most likely to affect English speaking users, since the note is written in English.
Rozena rat
Rozena is a Remote Access Trojan (RAT) that provides attackers with unauthorized access and control over affected systems.
Rozlok ransomware
Rozlok is a notorious ransomware encrypting victim's files and demanding payment in cryptocurrency.
Rransom ransomware
Rransom is a ransomware family known for encrypting files and demanding a ransom payment for decryption.
Rshell rat
Rshell is a remote access tool (RAT) used by cybercriminals to gain unauthorized access to victim machines.
RuMMS spywaretrojan
RuMMS is an Android malware family known for its ability to collect sensitive information from infected devices.
Rubeus credential-stealer
Rubeus is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.
Ruby ransomware
Ruby is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
Ruckguv rat
Ruckguv is a remote access tool (RAT) primarily used in cyber-espionage campaigns targeting government sectors.
RudeDevil ratbackdoor
RudeDevil is a remote access Trojan (RAT) primarily used for espionage and data stealing from government, financial, and tech sectors.
Rugmi trojanbackdoor
Also known as Penguish. Rugmi, also known as Penguish, is a sophisticated backdoor trojan used primarily for cyber-espionage activities.
Ruler exploit-kit
Ruler is a tool to abuse Microsoft Exchange services.
Rumish rat
Rumish is a remote access tool (RAT) primarily targeting government, financial, and telecommunications sectors.
RunExeMemory ransomware
RunExeMemory is a ransomware variant that encrypts files on infected systems and demands a ransom payment in cryptocurrency for file…
RunForestRun exploit-kit
Also known as Blackhole, Sutra. Active around 2012-2013, this family deployed small JavaScript snippets on infected websites to load exploit kit scripts from…
Running RAT ratkeyloggertrojan
Also known as running_rat. NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files.
RunningRAT rat
RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and…
Runsomewere ransomware
Ransomware Based on HT/EDA2 Utilizes the Jigsaw Ransomware background
Rurktar trojanspyware
Also known as RCSU. Rurktar, also known as RCSU, is a trojan spyware used for unauthorized access and information extraction.
Rush ransomware
Rush is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption keys.
RushDrop dropperrat
Also known as ChronosRAT. According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
Russenger ransomware
Russenger is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
Russian EDA2 ransomware
Russian EDA2 is a strain of ransomware designed to encrypt files on infected systems and demand a ransom for decryption.
Russian Globe Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
RussianRoulette ransomware
RussianRoulette is a ransomware variant evolving from the Philadelphia ransomware, aimed at encrypting user data to demand a ransom payment.
RustBucket (OS X) rat
RustBucket is a malware designed to target Mac OS X systems, often used for gaining remote access to compromised machines.
RustBucket (Windows) rat
RustBucket is a Remote Access Trojan (RAT) targeting Windows systems, primarily aimed at compromising governmental and financial…
Rustock botnet
Rustock is a sophisticated botnet malware that was primarily used for sending spam emails.
Rustonotto trojanrat
Also known as CHILLYCHINO. Rustonotto, active since June 2025, is a Rust-compiled malware, representing the first known instance of APT37 leveraging Rust-based…
RustyClaw downloader
According to Proofpoint, RustyClaw is a downloader written in Rust
RustyRocket trojanspyware
Written in Rust and designed for both Windows and Linux environments, RustyRocket enables WorldLeaks affiliates to steal data through…
RustyWater rat
Also known as Archer RAT / RUSTRIC. RustyWater is a Rust-based implant used by MuddyWater.
Ryuk ransomware
Ryuk is a ransomware designed to target enterprise environments that has been used in attacks since at least 2018.
Ryuk Stealer credential-stealerspyware
Also known as Sidoh. Information Stealer that searches for sensitive documents and uploads its results to an FTP server.